Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.0, 4.0-debian, 4.0-debian13, 4.0.6, 4.0.6-debian, 4.0.6-debian13

Index digest:

sha256:372a8d98e0088a91cd5758bb0cb3bf919458d4ffe39a9e15cdf1b1368c85834e

Manifest digest:

sha256:7636d04156dc8dab3d127000c24486537606ed46c89a60131ebe054facc914b3

Size

22.62 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:2e8ea7e703f723b1d970bffae5b0f324af3f0836b5553fd6d74c7b53b46355d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:b15046c620bc82b01c83fdb77464c4f23946d6671807e01b725a23f4767d1f53
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:c4ad23544df3bf0ef567085e51856b0ab4a154a6606b170d66bed726b5fba0f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:d2c3edf8d8bac20a408adf125cc07b0aa287e5db67cf6904fb7c79a262b971c5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:1ceb8d3aa47c0f32b39ce528422242db84aee009d9b0f2eaafdf1d4d17afab64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:9debe8a853ed7563b6c4992211662e69de9fa6f91f8a8bba15c0933fecbeecb0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:e09f48d269f730d40678e708a4b7493b7637c26153277f215ca50907b3d8747b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:8d18793c863c6ceabc417555b2a99d77569d5aa11435e937c3ec540b71a9fe61
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:6d0ca959a6bb539281f459e601d23556fc1d3baa1ef930cc929efec0a756d4ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:6970d618b68acb2a0beb3ba385f05beb5411d594af367a1f05af5c53f0ba2ee6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:e20cc7e0d537a402694d403285623b3c76a5a56a1a6688d289bc907a54f1ea43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:0f56275007f64e438655df7f771be92f82be343addb4e708a27d2fbc5218529f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:2cfb166291db35a3a1c7071f851f5f31d566912f3ef2b4d5917d69886361bfcb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:0a73b7657022a031288d236ec19d97153b8bd3d02410d506160f34b59c1213c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:595c84beb76e772b5e3c8c356e1c9919e31a90ea18af84dbc898dcdc11e5f558